The package has a clear license, useful documentation, regular releases, and an active non-archived repository. Organization ownership and a security policy help, but workflow references are not pinned, leaving avoidable build-integrity exposure.
72%
Total Score
83
93
83
One contributor made all 18 commits in the last three months, leaving maintenance continuity dependent on a single active individual.
The release is not marked prerelease, but the package remains below version 1.0, so some compatibility uncertainty remains despite stable recent releases.
Both workflows were analyzed successfully and have no untrusted checkouts, script injection, or audit findings, but all three action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.1.0|~3.2.0 | — | — |
hyperf/event Version ~3.1.0|~3.2.0 | — | — |
hyperf/logger Version ~3.1.0|~3.2.0 | — | — |
hyperf/command Version ~3.1.0|~3.2.0 | — | — |
hyperf/process Version ~3.1.0|~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.